Case Study of Security Development in an Agile Environment: Building Identity Management for a Government Agency

dc.contributor.authorKalle Rindell
dc.contributor.authorSami Hyrynsalmi
dc.contributor.authorVille Leppänen
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organizationfi=tietojenkäsittelytiede|en=Computer Science|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2606803
dc.converis.publication-id18227694
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/18227694
dc.date.accessioned2022-10-28T12:27:31Z
dc.date.available2022-10-28T12:27:31Z
dc.description.abstract<p>In contemporary software development projects and computing tasks, security concerns have an increasing effect, and sometimes even guide both the design and the project's processes. In certain environments, the demand for the security becomes the main driver of the development. In these cases, the development of the product requires special security arrangements for development and hosting, and specific security-oriented processes for governance. Compliance with these requirements using agile development methods may not only be a chance to improve the project efficiency, but can in some cases, such as in the case discussed in this paper, be an organizational requirement. This paper describes a case of building a secure identity management system and its management processes, in compliance with the Finnish government's VAHTI security instructions. The building project was to be implemented in accordance to the governmental security instructions, while following the service provider's own management framework. Project itself was managed with Scrum. The project's steering group required the use of Scrum, and this project may be viewed as a showcase of Scrum's suitability to multi-teamed, multi-site, security standard-compliant work. We also discuss the difficulties of fulfilling strict security regulations regarding both the development process and the end product in this project, and the difficulties utilizing Scrum to manage a multi-site project organization. Evaluation of the effects of the security work to project cost and efficiency is also presented. Finally, suggestions to enhance the Scrum method for security-related projects are made.</p>
dc.format.pagerange556
dc.format.pagerange563
dc.identifier.isbn978-1-5090-0990-9
dc.identifier.olddbid176541
dc.identifier.oldhandle10024/159635
dc.identifier.urihttps://www.utupub.fi/handle/11111/32001
dc.identifier.urlhttp://ieeexplore.ieee.org/document/7784619/
dc.identifier.urnURN:NBN:fi-fe2021042716219
dc.language.isoen
dc.okm.affiliatedauthorRindell, Kalle
dc.okm.affiliatedauthorHyrynsalmi, Sami
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryUnited Statesen_GB
dc.publisher.countryYhdysvallat (USA)fi_FI
dc.publisher.country-codeUS
dc.relation.conferenceInternational Conference on Availability, Reliability and Security
dc.relation.doi10.1109/ARES.2016.45
dc.source.identifierhttps://www.utupub.fi/handle/10024/159635
dc.titleCase Study of Security Development in an Agile Environment: Building Identity Management for a Government Agency
dc.title.bookProceedings of 11th International Conference on Availability, Reliability and Security (ARES)
dc.year.issued2016

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
ASSD__Case_Study_of_Scrum_VAHTI_final.pdf
Size:
416.24 KB
Format:
Adobe Portable Document Format
Description:
Final draft